← Back
CWE-20

12,840 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,840)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Pan Os
May 6, 2026
Apr 12, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API ca...Show more
The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.Show less
1Paloaltonetworks
1Pan Os
May 6, 2026
Apr 12, 2016
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administr...Show more
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.Show less
1Apache
1Struts
May 6, 2026
Apr 12, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
1Apache
1Ofbiz
May 6, 2026
Apr 12, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
2Debian
Inspircd
2Debian Linux
Inspircd
May 6, 2026
Apr 12, 2016
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) char...Show more
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.Show less
1Huawei
5S5300 Firmware
S5700 FirmwareS7700 Firmware+2 more
May 6, 2026
Apr 11, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service (switch restart) via crafted traffic.
5Canonical
DebianOpensuse+2 more
10Communications Billing And Revenue Management
Configuration ManagerDatabase Server+7 more
May 6, 2026
Apr 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
1Sap
1Application Server Java
May 6, 2026
Apr 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted HTTP request, aka SAP Security Note 2259547.
1Sap
1Java As
May 6, 2026
Apr 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the...Show more
Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the IctParseCookies function, aka SAP Security Note 2256185.Show less
2Debian
Rubyonrails
3Debian Linux
RailsRuby On Rails
May 6, 2026
Apr 7, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Apr 7, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Apr 7, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspec...Show more
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.Show less
2Fedoraproject
Nodejs
2Fedora
Node.js
May 6, 2026
Apr 7, 2016
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection...Show more
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.Show less
2Fedoraproject
Nodejs
2Fedora
Node.js
May 6, 2026
Apr 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
1Huawei
1P7 Firmware
May 6, 2026
Apr 7, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
Huawei Sophia-L10 smartphones with software before P7-L10C900B852 allow attackers to cause a denial of service (system panic) via a crafted application with the system or camera privilege.
1Netapp
1Clustered Data Ontap
May 6, 2026
Apr 7, 2016
N/A· v4
6.8 MEDIUM· v3
5.8 MEDIUM· v2
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
2Cisco
Sun
3Evolved Programmable Network Manager
OpensolarisPrime Infrastructure
May 6, 2026
Apr 6, 2016
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID...Show more
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.Show less
1Cisco
2Asa With Firepower Services
Firesight System Software
May 6, 2026
Apr 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.
1Cisco
2Ios
Nx Os
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug...Show more
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279.Show less
1Apple
1Iphone Os
May 6, 2026
Mar 24, 2016
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL an...Show more
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.Show less